René Helmke 7791f18b51 bootstrap
2023-05-16 16:09:41 +02:00

164 lines
5.4 KiB
JSON

{
"id": "CVE-2019-10920",
"sourceIdentifier": "productcert@siemens.com",
"published": "2019-05-14T20:29:02.637",
"lastModified": "2022-01-04T18:10:56.570",
"vulnStatus": "Analyzed",
"descriptions": [
{
"lang": "en",
"value": "A vulnerability has been identified in LOGO! 8 BM (incl. SIPLUS variants) (All versions < V8.3). Project data stored on the device, which is accessible via port 10005/tcp, can be decrypted due to a hardcoded encryption key. The security vulnerability could be exploited by an unauthenticated attacker with network access to port 10005/tcp. No user interaction is required to exploit this security vulnerability. The vulnerability impacts confidentiality of the device. At the time of advisory publication no public exploitation of this security vulnerability was known."
},
{
"lang": "es",
"value": "Se ha identificado una vulnerabilidad en LOGO!8 BM (incluidas las variantes SIPLUS) (todas las versiones anteriores a la versi\u00f3n V8.3). Los datos del proyecto almacenados en el dispositivo, al que se puede acceder por medio del puerto 10005/tcp, puede ser descifrado debido a una clave de cifrado codificada. La vulnerabilidad de la seguridad podr\u00eda ser explotada por un atacante no identificado con acceso de red al puerto 10005/tcp. No se requiere la interacci\u00f3n del usuario para explotar esta vulnerabilidad de seguridad. La vulnerabilidad afecta a la confidencialidad del dispositivo. En el momento de la publicaci\u00f3n de asesoramiento, no se conoc\u00eda la explotaci\u00f3n p\u00fablica de esta vulnerabilidad de seguridad"
}
],
"metrics": {
"cvssMetricV31": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"cvssData": {
"version": "3.1",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
"attackVector": "NETWORK",
"attackComplexity": "LOW",
"privilegesRequired": "NONE",
"userInteraction": "NONE",
"scope": "UNCHANGED",
"confidentialityImpact": "HIGH",
"integrityImpact": "NONE",
"availabilityImpact": "NONE",
"baseScore": 7.5,
"baseSeverity": "HIGH"
},
"exploitabilityScore": 3.9,
"impactScore": 3.6
}
],
"cvssMetricV2": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"cvssData": {
"version": "2.0",
"vectorString": "AV:N/AC:L/Au:N/C:P/I:N/A:N",
"accessVector": "NETWORK",
"accessComplexity": "LOW",
"authentication": "NONE",
"confidentialityImpact": "PARTIAL",
"integrityImpact": "NONE",
"availabilityImpact": "NONE",
"baseScore": 5.0
},
"baseSeverity": "MEDIUM",
"exploitabilityScore": 10.0,
"impactScore": 2.9,
"acInsufInfo": false,
"obtainAllPrivilege": false,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
]
},
"weaknesses": [
{
"source": "productcert@siemens.com",
"type": "Primary",
"description": [
{
"lang": "en",
"value": "CWE-321"
}
]
},
{
"source": "nvd@nist.gov",
"type": "Secondary",
"description": [
{
"lang": "en",
"value": "CWE-798"
}
]
}
],
"configurations": [
{
"operator": "AND",
"nodes": [
{
"operator": "OR",
"negate": false,
"cpeMatch": [
{
"vulnerable": true,
"criteria": "cpe:2.3:o:siemens:logo\\!8_bm_firmware:*:*:*:*:*:*:*:*",
"matchCriteriaId": "8BD8930B-3FD2-4F4B-9B75-A68A8DA3B4CA"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:o:siemens:logo\\!8_bm_firmware:*:*:*:*:*:*:*:*",
"versionEndExcluding": "8.3",
"matchCriteriaId": "04B5476E-E575-4513-A066-A8B5E998B257"
}
]
},
{
"operator": "OR",
"negate": false,
"cpeMatch": [
{
"vulnerable": false,
"criteria": "cpe:2.3:h:siemens:logo\\!8_bm:*:*:*:*:*:*:*:*",
"matchCriteriaId": "A7F0DF04-E086-4C3F-A083-7E36165AC85E"
}
]
}
]
}
],
"references": [
{
"url": "http://packetstormsecurity.com/files/153122/Siemens-LOGO-8-Hard-Coded-Cryptographic-Key.html",
"source": "productcert@siemens.com",
"tags": [
"Third Party Advisory",
"VDB Entry"
]
},
{
"url": "http://seclists.org/fulldisclosure/2019/May/44",
"source": "productcert@siemens.com",
"tags": [
"Mailing List",
"Third Party Advisory"
]
},
{
"url": "http://www.securityfocus.com/bid/108382",
"source": "productcert@siemens.com",
"tags": [
"Third Party Advisory",
"VDB Entry"
]
},
{
"url": "https://cert-portal.siemens.com/productcert/pdf/ssa-542701.pdf",
"source": "productcert@siemens.com",
"tags": [
"Vendor Advisory"
]
},
{
"url": "https://seclists.org/bugtraq/2019/May/72",
"source": "productcert@siemens.com",
"tags": [
"Mailing List",
"Third Party Advisory"
]
}
]
}